Company isolation
SECURITY
Trust begins with clear access boundaries.
Security in Opearia covers identity, membership, roles, data scope, audit and environment separation.
The public site explains the security model for business assessment without publishing keys, internal identifiers or attack-relevant implementation detail.
ACCESS ARCHITECTURE
Access is not one rule. It is a sequence of independent boundaries.
RLS and permitted scope
Roles, membership and audit
SECURITY / TRUST CENTER
Facts, status and open questions in one place.
No unapproved certifications or broad claims. Every control is presented with an explicit status.
Access control
Roles, active memberships and permitted scope determine available functions.
Data isolation
Tenant context and RLS provide separate access boundaries.
Audit and accountability
Owner, status and key action changes remain attached to the case.
Integrations and hosting
Architecture, region, subprocessors and retention are confirmed for the agreed scope.
DATA AND ISOLATION
Layered access control
Tenant isolation
Company data is separated through membership, permitted scope and database access rules.
PostgreSQL RLS
Row Level Security adds a control layer that restricts rows according to the user context.
Roles and permissions
Functions and actions are available only under a confirmed role and active membership.
OPERATIONAL PROTECTION
Control across the lifecycle
- 01Supabase Cloud and PostgreSQL as a managed cloud foundation
- 02Audit of relevant activity and change
- 03MFA for SuperAdmin access
- 04Server-side storage of secrets and service keys
- 05Separate staging and production environments
- 06Controlled module activation by company and contract
- 07Least-privilege access reviews
RESPONSIBILITY
Security is a shared process.
Opearia protects the platform and access boundaries. Clients manage their users, devices, internal policies and accuracy of assigned roles.